Download PDF
NAVEX > Case Studies > Major Health Insurer Manages Vendor Risk with NAVEX Global’s GRC Platform
NAVEX Logo

Major Health Insurer Manages Vendor Risk with NAVEX Global’s GRC Platform

Technology Category
  • Platform as a Service (PaaS) - Data Management Platforms
Applicable Industries
  • Healthcare & Hospitals
Applicable Functions
  • Procurement
Use Cases
  • Regulatory Compliance Monitoring
Services
  • System Integration
The Challenge
The major health insurer was struggling to comply with HIPAA data security requirements and other regulations due to inefficient manual processes for vendor risk management. The company had previously adopted a GRC platform, but it proved to be overly rigid and required technical expertise to configure, leading the risk management team to revert to manual processes. The company needed a more advanced GRC platform that could streamline vendor risk assessments, comply with healthcare regulations, require little or no IT assistance, and achieve high user adoption.
About The Customer
The customer is a major health insurer in the United States. Like most in the healthcare industry, the company complies with the Health Insurance Portability and Accountability Act (HIPAA), as well as many other regulations and requirements. A primary HIPAA compliance requirement for the company is assessing vendors regularly, as well as assessing vendors’ third parties. Compliance failures can lead to stiff fines. The company had previously relied on manual processes for vendor risk management activities like issuing assessments, which proved to be inefficient and error-prone.
The Solution
The health insurer adopted NAVEX Global’s Lockpath, a flexible and scalable solution for integrated risk management that includes the ability to streamline vendor risk assessments. Lockpath was easy to configure to the health insurer’s processes and enhanced the company’s ability to identify, analyze, track, and report on vendor risks. The platform allowed the IT Risk team to enforce its defined vendor risk assessment process, ensuring vendors have the proper security controls in place to meet HIPAA requirements for protecting patient data. The team assesses vendors by issuing questionnaires internally with staff who each represent a segment of the vendor base. Comprehensive questionnaires help the health insurer identify security control gaps that are tracked as findings within Lockpath’s risk register. As third parties remediate their findings, their risk score is reduced, which lowers the insurer's overall third party risk.
Operational Impact
  • The health insurer now has a central repository for all risk data, which is correlated, analyzed, and delivered in management and executive-ready reports.
  • The IT risk manager uses the platform to produce automated monthly metric reports for his CISO.
  • The health insurer can report on everything from internal IT risks and cybersecurity incidents to IT audit findings and vendor risks.

Related Case Studies.

Contact us

Let's talk!

* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.